Cookies notice
What cookies Wehoz sets, what each one does, and how to manage your choices.
title: Cookies notice description: What cookies Wehoz sets, what each one does, and how to manage your choices. topic: policies order: 30 updated_at: "2026-05-30" effective_date: "2026-05-30" version: "v1.0" tags: [cookies, tracking, gpc]
1. What is a cookie
A cookie is a small text file a website asks your browser to store, so the site can recognize you between page loads or visits. Cookies are scoped to the site that set them — they can't read data from other sites.
We also use similar technologies (local storage, session storage). For simplicity we refer to all of them as "cookies" in this notice.
2. The cookies we set
Essential — always on
| Name | Purpose | Lifetime |
|---|---|---|
whz_cart | Identifies your shopping cart (anonymous) | 90 days |
whz_session | Authenticated session (signed-in users) | Session |
sb-* | Supabase auth tokens | 30 days |
whz_csrf | Cross-site request forgery protection | Session |
whz_cookies_ok | Records your cookie preferences | 12 months |
You can't turn these off — the cart and sign-in stop working if you block them.
Analytics — opt-in
| Name | Purpose | Lifetime | Provider |
|---|---|---|---|
ph_* | PostHog product analytics + session replay (inputs masked) | 12 months | PostHog |
_ga | Google Analytics 4 unique visitor ID | 24 months | Google Analytics |
_ga_* | GA4 session state | 24 months | Google Analytics |
These run only after you accept the consent banner. We honor Global Privacy Control — if your browser sends a GPC header, we treat it as a no by default and these cookies never set.
Performance — always on
| Name | Purpose | Lifetime |
|---|---|---|
__cf_bm | Cloudflare bot-mitigation challenge token | Session |
whz_geo | Approximate region for currency/tax estimates | 30 days |
Performance cookies don't identify you personally. They help the Service run reliably.
3. Managing your preferences
- First visit — a consent banner asks you to accept or decline analytics cookies. Your choice is recorded.
- Anytime after — open the Cookie preferences link in the footer (Phase 1.1 — temporarily until shipped, you can clear cookies in your browser settings, which resurfaces the banner).
- Browser-level controls — every modern browser lets you block cookies entirely or by site. Doing so may break sign-in or cart persistence.
- Global Privacy Control — supported. We treat a GPC header as an opt-out across the Service.
4. Third-party cookies
We don't allow third-party advertising cookies. The third parties referenced above (PostHog, Google Analytics, Cloudflare, Supabase) only set cookies needed for their own service to function.
5. Changes to this notice
If our cookies change, we update the Effective date above. Material changes (new tracking technology, new advertising tech) require a fresh consent banner — we won't silently expand collection.
Questions: privacy@wehoz.com.